๐Ÿ” CVE Alert

CVE-2026-0654

UNKNOWN 0.0

Command injection on TP-Link Deco BE25

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. An authenticated adjacent attacker may execute arbitrary commands via crafted configuration file, impacting confidentiality, integrity and availability of the device. This issue affects Deco BE25 v1.0: through 1.1.1 Build 20250822.

CWE CWE-78
Vendor tp-link systems inc.
Product deco be25 v1.0
Published Mar 2, 2026
Last Updated Mar 11, 2026
Stay Ahead of the Next One

Get instant alerts for tp-link systems inc. deco be25 v1.0

Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. deco be25 v1.0 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TP-Link Systems Inc. / Deco BE25 v1.0
0 โ‰ค 1.1.1 Build 20250822

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
tp-link.com: https://www.tp-link.com/sg/support/download/deco-be25/#Firmware tp-link.com: https://www.tp-link.com/en/support/download/deco-be25/#Firmware tp-link.com: https://www.tp-link.com/us/support/download/deco-be25/v1/#Firmware tp-link.com: https://www.tp-link.com/us/support/faq/4993/

Credits

caprinuxx